Authentication
Create, send, rotate, and revoke Drex API keys.
Every request to https://console.nace.ai carries an API key in the Authorization header. Keys spend the credit of the account that created them. This guide covers the key lifecycle from creation to revocation.
Create a key
- Sign in at console.nace.ai/login and open API Keys.
- Click Create key.
- Enter a name, such as the app or environment that will use the key, and click Create key.
- Copy the key from the dialog.
The full key appears once. After you close the dialog, the API Keys page shows only the key's prefix. If you lose a key, revoke it and create a new one.
A key looks like nace_sk_ followed by 43 URL-safe characters. An account can have at most 3 active keys. When you reach the limit, Create key is disabled until you revoke one.
Store the key
Put the key in an environment variable or a secret manager. Do not commit it to source control, and do not ship it in code that runs in a browser or a mobile app.
export DREX_API_KEY="nace_sk_..."The TypeSafe SDK reads the key from TYPESAFE_API_KEY when you do not pass apiKey. See Migrate from TypeSafe for the full environment setup.
Send the key
Send the key as a Bearer token on every request.
curl https://console.nace.ai/v1/models \
-H "Authorization: Bearer $DREX_API_KEY"Keep the key on the server
Only call Drex from code you control on a server. Anyone who loads a page can read a key shipped in its JavaScript.
The TypeSafe SDK enforces this. If TypeSafeClient is constructed in a browser, the constructor throws a TypeSafeError:
TypeSafeClient is running in a browser, which would expose your API key to anyone using the page. Call the API from a server instead, or pass
dangerouslyAllowBrowser: trueif you understand the risk.
Pass dangerouslyAllowBrowser: true only in a context where exposing the key is acceptable, such as a local demo. For a web app, call Drex from your own backend and have the browser call your backend.
Rotate a key
To rotate a key without downtime:
- On API Keys, click Create key and create the replacement. If you already have 3 active keys, revoke an unused one first.
- Deploy the new key to your servers and confirm that requests succeed.
- Click Revoke next to the old key, then confirm with Revoke key.
Requests with the revoked key stop working within 5 seconds. Revocation cannot be undone.
Revoke a key
To revoke a key you no longer need, or one that may have leaked, open API Keys, click Revoke on that row, and confirm with Revoke key. A revoked key stays in the list with the status Revoked so you can see when it was last used.
What a bad key returns
A missing, malformed, or revoked key returns 401 with the type authentication_error. This is a real capture from curl -i https://console.nace.ai/v1/models with no Authorization header. The request id varies per call.
HTTP/2 401
x-request-id: req_7c1e4a9b2d3f4e5a8b6c7d8e9f0a1b2c
x-typesafe-request-id: req_7c1e4a9b2d3f4e5a8b6c7d8e9f0a1b2c
access-control-expose-headers: retry-after, retry-after-ms, x-request-id, x-typesafe-request-id
{
"error": {
"type": "authentication_error",
"message": "Invalid API key. Pass a nace_sk_ key as `Authorization: Bearer <key>`."
},
"request_id": "req_7c1e4a9b2d3f4e5a8b6c7d8e9f0a1b2c"
}The TypeSafe SDK raises this as an AuthenticationError and does not retry it. Every Drex response carries the same request id in the body and in both headers. Quote it when you contact support. Other error types are listed in Errors.
Check a key without spending credit
GET /v1/models needs a valid key but works when the account has no credit, so you can use it to confirm that a key is active before you deploy it.
curl https://console.nace.ai/v1/models \
-H "Authorization: Bearer $DREX_API_KEY"{
"models": [
{
"name": "drex-v1.0",
"description": "Drex System One decision model. Typed questions in, calibrated probabilities out.",
"release_date": "2026-09-24",
"alias_for": null
},
{
"name": "drex-v1.5",
"description": "Drex 1.5 decision model. Typed questions in, calibrated probabilities out; states up to 131,072 tokens.",
"release_date": "2026-09-28",
"alias_for": null
},
{
"name": "drex-latest",
"description": "Points to drex-v1.5 (Drex 1.5). Moves to a newer version only on an announced date.",
"release_date": "2026-09-28",
"alias_for": "drex-v1.5"
},
{
"name": "drex-v1.1",
"description": "Retired on 2026-09-28. Requests that name it are served by drex-v1.5 (Drex 1.5) at its price.",
"release_date": "2026-09-25",
"alias_for": "drex-v1.5"
}
],
"request_id": "req_0a2b4c6d8e1f4a3b9c5d7e9f1a3b5c7d"
}A POST /v1/systemone call with a valid key and no credit returns 402 with the type insufficient_credit. Top up or add a card on Billing to keep going. An account with an unpaid invoice gets 402 with the type payment_required until the invoice is paid on Billing. See Pricing.